In this blog
- The Fundamental Backup Problem
- The Problem with Legacy Platforms
- Your Recovery is Vulnerable
- The Threat from Modern Adversaries
- Surviving AI-Accelerated Attacks
- Building True Resilience with Rubrik Security Cloud
- RSC Architecture
- Preemptive Recovery: Recover Before the Attack Even Starts
- Cyber Resilience with Rubrik
Taking precautions to prevent cyberattacks is important. But when defenses inevitably fail, fast recovery matters most. It’s no longer a question of if a breach occurs, but how quickly operations can resume when your systems are breached.
According to CrowdStrike, 82% of breaches are malware-free, instead using identity techniques. So, ideally, IdPs like Active Directory and Entra ID must not be exposed to risk of being tampered with or deleted.
This makes secure, tamper-resistant backups critical.
The Fundamental Backup Problem
Unfortunately, most conversations about identity resilience focus on recovery time objectives (RTOs) and backup frequency. But these discussions hide a critical flaw: if your backup solution relies on the very same platform that was just breached, your last line of defense is already compromised.
For years, organizations have depended on the same underlying platform or operating system to run production workloads and execute their recovery. The irony is stark: an organization's last line of defense relies on the very platform that was just breached and failed.
Using a platform with proven security gaps as the final safeguard is a fatal architectural flaw. If this was stated plainly to a board of directors, they would never support this approach to identity recovery. How long is it until that separation in platforms is a requirement by the board or by cyber security insurance?
The Problem with Legacy Platforms
Legacy platforms turn IdP protection into an infrastructure project. Organizations end up purchasing, racking, patching, and babysitting an entire second stack just to back up Active Directory or Entra ID.
That stack is never free. Stacked OS and software licensing, hypervisor seat fees, dedicated storage appliances, and upfront over-provisioning for years of growth capacity all drive up Total Cost of Ownership (TCO).
Additionally, these software-only options carry ongoing management, vendor patching, and compute overhead. And because software is built for features and usability rather than security, the fix is usually more software stacked on software—paradoxically increasing risk.
The operational cost is worse than the financial one. Parallel infrastructure means security teams spend more time patching backup servers than investigating actual threats. SecOps teams routinely lose up to half their operational bandwidth to this kind of maintenance, while standard patch cycles still lag, leaving recovery systems exposed right alongside production.
This approach flies in the face of ongoing tool consolidation efforts and executive mandates to streamline operations. Moreover, it runs counter to where the industry is headed. Modern cloud initiatives don't leave room for a local, infrastructure-heavy backup architecture bolted onto the side.
And going virtual doesn't fix it either. Virtualized systems introduce their own hypervisor-level vulnerabilities and still share credential domains and host attack surfaces with production.
To reiterate, the real problem is architectural. Running backup management on the same control plane as production, whether that means a shared Active Directory domain or hypervisor layer, creates one shared attack surface instead of two independent ones.
Your Recovery is Vulnerable
Ransomware groups understand this architectural problem and target local backup consoles first. If the fallback depends on standard commercial operating systems, shared credential domains, or a single compromised admin account, an attacker who owns production owns recovery too.
That dependency only gets more dangerous as the attack surface expands across Non-Human Identities (NHIs) and AI-driven workloads,and can't survive a single OS-level exploit. One compromise becomes a fatal single point of failure for the whole environment.
It gets worse. Native restore methodologies for on-premises Active Directory are more than two decades old, are exceptionally complex, and heavily manual. Administrators must execute tedious, domain-by-domain recovery procedures that require meticulous forest recovery planning, manual authoritative restores, and painstaking object reconciliation. Manually restoring a complex Active Directory forest typically takes three to seven days. That timeline extends to weeks if backup data is corrupted or hit by ransomware. Without rapid operational recovery, organizations can't achieve modern RTOs.
To survive today's cyber-attacks, the platform protecting and restoring enterprise data must be secure, resilient, and engineered to run out-of-band, completely isolated from the environment it protects.
The Threat from Modern Adversaries
Modern threat groups including Conti, LockBit, Scattered Spider, and ALPHV/BlackCat actively exploit these architectural weaknesses. They seek out and destroy backup infrastructure, erasing Volume Shadow Copies, local vaults, and identity recovery points before detonating their main payloads to force a ransom payout.
During the February 2024 attack on Change Healthcare, the ALPHV/BlackCat threat group exploited 9 days of dwell time (gained via an un-MFA-protected remote access portal) to systematically compromise the healthcare organization’s recovery infrastructure. Adversaries used harvested domain administrator credentials to traverse the internal network. They located and neutralized secondary data repositories, disabling retention features and encrypting backup vaults—prior to final payload detonation. Ultimately, deliberately destroying local recovery points and eliminating an out-of-band restore options severely extended operational downtime. The attackers forced the organization to rebuild core environments in clean-room staging and pay a $22 million ransom.
In 2025, the Medusa Ransomware Campaign against Critical Sector Infrastructure, drove a sharp increase in time-delayed payload injection. Threat actors injected payloads into backup snapshots 14 to 45 days before detonating, ensuring that when organizations tried to roll back to earlier backups, the restored environments were already compromised.
Digging deeper, the Medusa Ransomware Campaign exemplifies how modern ransomware as a service (RaaS) actors target the identity and recovery layers to enforce double extortion. Using native remote management tools and harvested domain credentials, Medusa operators quietly navigated target environments to execute credential dumps and escalate Active Directory privileges. They systematically terminated backup services, purged local Volume Shadow Copies, and shut down hypervisors to destroy live recovery points.
Then, they detonated their encryptor payload.
This strategy rendered traditional local backups useless, leaving victims with no alternative but to rebuild from an isolated, out-of-band architecture or endure prolonged operational downtime.
Surviving AI-Accelerated Attacks
To survive today’s cyberattacks and everything that lies ahead with the advancements in weaponizing AI, identity data must be sent directly to an out-of-band, immutable, multi-factor authentication (MFA)-enforced, zero-trust architecture removing local intermediary attack vectors. These third-party vendors shouldn’t be “bolted on” to patch capability gaps; doing so violates the zero-trust framework.
Rubrik’s platform builds this functionality by default, offering native immutability, indelibility, time-based one-time password (TOTP), and MFA. Rubrik natively aligns with zero-trust principles and protects against modern cyberattacks in a way legacy platforms simply aren’t built to do.
Building True Resilience with Rubrik Security Cloud
True resilience requires shifting to an out-of-band, cloud-native architecture that enforces strict control-plane separation. Rubrik’s platform isn’t part of the forest or domain, it doesn’t log in through the organization’s Active Directory, and it doesn’t run on the same platform. There’s no local middleman left for an attacker to hijack. There’s no path in.
An immutable, MFA-enforced platform ensures that even if primary production systems are fully compromised, the recovery layer remains isolated, untouched, and ready to restore. This delivers real security without the burden of managing a second platform. Rubrik is a fully hosted, out-of-band SaaS platform that provides the isolation required to guarantee that backup data survives intact and can be safely restored outside the blast radius of a compromised domain.
This is where Rubrik Security Cloud (RSC) shines. RSC addresses these identity and platform vulnerabilities through complete control-plane separation. A compromised customer identity boundary cannot propagate into the management plane because the platform is explicitly engineered without trust dependencies on customer identity infrastructure.
RSC is running instead on a custom, hardened proprietary OS designed strictly to remove traditional server attack surfaces. Engineered to protect multiple Active Directory forests concurrently within a single control plane, the platform operates entirely outside the forests it protects, ensuring it remains completely isolated from their blast radius. Delivered as a cloud-native SaaS platform built on Google Cloud Platform (GCP) microservices, RSC provides an out-of-band "bunker in a box" architecture designed to survive total environment compromise.
Every critical safeguard, including append-only immutable and indelible storage, isolated vaults, and mandatory MFA, is incorporated natively to enforce a strict zero-trust model without requiring third-party add-ons or complex external dependencies. Built on a rigorous Secure Software Development Lifecycle (SSDLC) with API-gated role-based access control (RBAC), RSC ensures that backup data cannot be encrypted, altered, or deleted even by an administrator with compromised domain credentials.
RSC Architecture
While restoring multiple Domain Controllers simultaneously addresses the critical need for speed, returning to a verified trusted state is paramount. If an organization restores infected data, the recovery process becomes a meaningless exercise, forcing a second round of downtime when dormant payloads detonate.
Finding clean data requires scanning backup snapshots for persistent threats and indicators of compromise (IOCs) and indicators of exposure (IOEs) before data hits production, ensuring the environment is secure and stays secure. This threat hunting operates on two complementary levels:
Metadata-based detection: Searches for known file names, file-hash signatures, and file "magic bytes," identifying indicators of compromise without ever opening the file's contents.
Content-based detection: Searches within file contents for hex values, ASCII and Unicode strings, and regular expressions, allowing rules to be built around emerging threats rather than relying solely on a static list of known-bad hashes.
The RSC architecture means the backup data never leaves the local environment for scans, verifying that the data is clean. Scanning happens on Rubrik's platform itself, so there is no impact on production systems, no maintenance window is required. The scan is invisible to anything watching the production network, so an advanced persistent threat (APT) lurking in the environment has no way to detect that it is being hunted.
The platform can process multiple rules across multiple objects at multiple points in time in a single pass. This helps teams identify an adversary’s entry point and subsequent lateral movement. Once a threat is confirmed, Rubrik can quarantine it to prevent reinfection, and granular RBAC lets SecOps teams recover suspect data into an isolated environment for testing without granting them broader recovery access.
Preemptive Recovery: Recover Before the Attack Even Starts
Rubrik is squarely focused on accelerating customer cyber recovery times with a proprietary Preemptive Recovery Engine™, a technology that powers faster and more confident recovery without requiring infrastructure expansion or the mounting of an offline ntds.dit copy. These continuous scans execute out-of-band on the isolated RSC platform across on-premises, cloud, and SaaS environments so threat hunting operations remain completely invisible to any adversary lurking in the environment.
Additionally, Rubrik correlates these insights to preemptively begin the cyber recovery process. The engine combines pre-computed hashing with time-series intelligence to quickly identify clean recovery points without additional servers or third-party tools.
What sets Rubrik apart is this unified platform approach integrating identity intelligence, providing a complete picture of potential attacks alongside an end-to-end orchestrated cyber recovery solution with quarantining capabilities that dramatically expedite RTOs compared to toggling between disparate platforms.
But scanning clean recovery points means little if the underlying platform itself can be compromised. The key mechanism driving the platform's resilience is control-plane identity isolation. A common failure mode in ransomware incidents is identity blast radius. Once an attacker owns Active Directory, they own everything that trusts AD, including, legacy architected backup products, the backup management plane itself.
Rubrik’s RSC control plane does not authenticate itself using customer identity infrastructure, nor is it discoverable on the internal network or a part of the blast radius. If a backup platform or its storage repositories maintain local DNS records or reachable IP pathways, an attacker will inevitably find and target them.
A foundational element of Rubrik’s model is its encryption architecture, which moves past basic compliance checkboxes to enforce true cryptographic defense in depth. By leveraging this model, the platform guarantees both data confidentiality and cryptographic integrity, ensuring that any unauthorized attempt to alter or inspect backup payloads is immediately rendered inert and detected.
Cyber Resilience with Rubrik
Traditional Active Directory recovery and general-purpose platforms weren't built for these types of threats. Shared dependencies and discoverable networks don't just create risk. They create a single point of failure, and that's a fatal foundational flaw.
Real cyber resilience only comes one way. It is architecture built entirely outside the production identity boundary, walled off from the environment it protects, from the ground up. That's Rubrik Security Cloud. A fully integrated, cloud-native bunker in a box. Natively engineered for zero-trust. Complete control-plane isolation—built in, not bolted on.
Ultimately, architecture is the single deciding factor in surviving total environment compromise, today’s cyber-attacks; and what lies ahead. When identity recovery matters most, you can rely on Rubrik’s architecture.
SAFE HARBOR
Any unreleased services or features referenced in this document are not currently available and may not be made generally available on time or at all, as may be determined in our sole discretion. Any such referenced services or features do not represent promises to deliver, commitments, or obligations of Rubrik, Inc. and may not be incorporated into any contract. Customers should make their purchase decisions based upon services and features that are currently generally available.